CPENT Iot And OT Exploitation Practice Question
A security engineer is hardening an industrial SCADA environment against remote attacks. Which THREE of the following mitigation strategies are recommended best practices for securing OT networks? (Choose THREE)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploying industrial Intrusion Detection Systems (IDS) capable of parsing proprietary OT protocols (e.g., Modbus, DNP3, S7)
Securing OT networks involves strict Purdue model network segmentation, deploying unidirectional security gateways (data diodes), and implementing industrial IDS solutions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploying industrial Intrusion Detection Systems (IDS) capable of parsing proprietary OT protocols (e.g., Modbus, DNP3, S7)
Why this is correct
Industrial IDS solutions monitor for anomalous command sequences and unauthorized protocol operations on the control network.
- ✓
Utilizing unidirectional security gateways (data diodes) where data must flow from OT to IT without permitting inbound return paths
Why this is correct
Data diodes physically ensure that external networks cannot send control commands or traffic back into the critical control zone.
- ✗
Allowing unrestricted direct Internet access from all PLC controllers for automated driver updates
Why it's wrong here
Direct Internet access from PLCs is a severe security risk that exposes industrial controllers to direct external exploitation.
- ✗
Disabling all encryption across SCADA servers to improve packet inspection speeds on firewalls
Why it's wrong here
Disabling encryption degrades security by exposing cleartext credentials and control commands to packet sniffers.
- ✓
Implementing strict network segmentation between IT corporate networks and OT plant floors using firewalls
Why this is correct
Network segmentation prevents attackers who compromise the enterprise IT network from easily pivoting into the OT environment.
About these practice questions
Courseiva writes every CPENT question from scratch — 274 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.